Skip to content

Security described through its mechanisms, not superlatives.

This page presents what is verifiable in the current product. It claims no certification or guarantee we cannot document.

Mechanisms verified in the product · August 2026
01

Separation by school

Every application record is tied to its school's scope. Server-side controls prevent one school from reading another's scope.

VERIFIED · AUGUST 2026
02

Verified database connection

The connection between the server and the database uses TLS with certificate verification.

VERIFIED · AUGUST 2026
03

Protected two-factor authentication

Two-factor secrets are encrypted, and backup codes are never stored in plain text.

Technical detail: AES-256-GCM encryption.
VERIFIED · AUGUST 2026
04

Auditable documents

Generation, deletion, and reprinting of official documents are recorded in an audit log.

VERIFIED · AUGUST 2026

A specific security question?

Describe your context, your access requirements, or your audit needs. We'll answer based on the mechanisms actually in place.

Contact the team